|
试了一天多,还是出现错,我已经用了FORMAT........
代码如下 :
<%
Function genSQLstr()
Dim sId,PurBd,PurBd2
sId=session("sId")
PurBd= FormatDateTime(Date, 1)
PurBd2= FormatDateTime(Date, 1)
if Request.Form("PurBn")<>"" then
StrSQL=StrSQL+"where sBillNo like '%"+Request.Form("PurBn")+"%'"
else
StrSQL=StrSQL+"where sSuppId='"& sId &"'"
end if
if Request.Form("PurBd")<>"" and Request.Form("PurBd2")<>"" then
StrSQL=StrSQL+"and dBillDay between '%"+Request.Form("PurBd")+"%' and '%"+Request.Form("PurBd2")+"%'"
end if
if Request.Form("PurBrd")<>"" then
StrSQL=StrSQL+"and dRecDate = '%"+Request.Form("PurBd")+"%'"
end if
' 只获取到自己的订单
strSQL=strSQL & " and sSuppId='" & Replace(sId,"'","''") & "'" ' 防止注入攻击 |
|